Menu

#47 denyhosts uses insecure plain text protocol for synchronisat

open-rejected
nobody
None
5
2010-05-25
2010-01-12
Anonymous
No

Big security problem! The denyhosts sync service use http to sync ip addresses.

Discussion

  • Robert Wyatt

    Robert Wyatt - 2010-01-12

    Out of curiosity, why is it a problem to send banned IP addresses in plain text?

     
  • Phil Schwartz

    Phil Schwartz - 2010-05-25
    • status: open --> open-rejected
     
  • rosch

    rosch - 2012-10-14

    Because the content can be messed with and the sync will not work any more as expected or the wrong addresses get added to hosts.deny.

     

Log in to post a comment.